The Ship Is Already a Sensor
Modern merchant ships already carry dense networks of sensors, radios and computers. The COSCO allegation shows why maritime security increasingly depends on technical baselines, evidence and precise attribution.

U.S. allegations against COSCO point to a problem larger than one shipping company: as merchant vessels become dense networks of radios, sensors and computers, port security increasingly depends on proving what ordinary maritime technology is actually being used to do.
A modern container ship reaches port carrying far more than cargo. Its bridge and machinery spaces are built around radar, satellite-navigation receivers, automatic identification equipment, radios, computers, data recorders and antennas that continuously receive, process and exchange information required for navigation, safety and commercial operation. The Automatic Identification System alone transmits a vessel’s identity, position, course and speed while receiving corresponding information from surrounding ships, and contemporary navigation equipment increasingly works through interconnected digital systems rather than as a collection of independent instruments. At a port such as Busan, the presence of dense electronic equipment aboard a foreign vessel is consequently neither exceptional nor inherently suspicious; it is the technical baseline of commercial shipping.
That ordinary fact acquired a different significance on September 1, when Reuters reported that two senior U.S. officials believe some vessels operated by COSCO, China’s state-owned shipping group, have carried concealed equipment capable of collecting signals intelligence for Beijing. The officials described the alleged systems as more sophisticated than normal commercial communications equipment and said the collection concerned military communications technology and advances in encryption, but they did not identify the ships, disclose the equipment or release technical material that could be examined independently. COSCO did not respond to Reuters, while the Chinese Embassy in Washington rejected the allegations. Nothing in the public account identifies a COSCO vessel calling at Busan as having conducted intelligence collection in Korean waters.
Those limitations do not make the allegation unimportant; they define the question that can responsibly be asked of it. If a commercial vessel were being used for signals collection, investigators would gain relatively little from establishing that it carried an antenna, receiver or computer, since large merchant ships already carry such equipment in abundance. They would need to determine what a particular system was configured to receive, how it processed or retained the resulting data, when it operated, whether its activity corresponded with military or government systems, and where the information went afterward. The political significance of the equipment would emerge only from that technical and operational record.
For ports built around international trade, the difference is consequential. Nationality, state ownership and advanced electronics may all influence a security assessment, particularly when intelligence points toward a specific vessel or operator, but none can serve as a reliable substitute for evidence of conduct. At the same time, the growing sophistication of normal commercial shipping makes it easier for unusual capabilities to exist inside an electronic environment that is already complex. The security problem therefore begins with a deceptively simple requirement: authorities need to understand what a normal ship looks like technically before they can recognize when one of its systems is doing something that normal commercial operation does not explain.
Signals, Systems and Evidence
Radio systems reveal themselves differently according to how they operate. A transmitter places energy into the electromagnetic spectrum as part of its normal function, leaving observable characteristics such as frequency, timing, location and transmission pattern. A receiver works with signals that already exist around the vessel and does not need to broadcast what it is monitoring, why a particular part of the spectrum matters or what happens to the collected data after reception. Spectrum monitoring can therefore provide considerable information about an unusual transmitter while offering less certainty about the purpose of equipment whose principal function is to listen.
The distinction matters because commercial vessels already operate inside a dense radio-frequency environment. AIS exchanges identification and movement information over VHF; satellite-navigation systems provide position and timing; radar interprets reflected radio energy; satellite terminals connect vessels with shore offices; and onboard computers combine information from navigation, machinery and commercial systems. None of these ordinary functions amounts to the sort of intelligence collection alleged by the U.S. officials, yet together they explain why the appearance of a receiver, processor or storage device tells an investigator very little without a detailed understanding of the ship in which it is installed. A component absent from original construction drawings may have been added during an entirely legitimate refit, while a system capable of handling substantial volumes of data may be performing nothing more exotic than navigation, maintenance or remote machinery monitoring.
Radio emissions can nevertheless reveal more than the content of an intelligible communication. Their location, timing, frequency characteristics and repetition can provide information about the presence and behavior of the systems producing them, particularly when observations are combined with data gathered elsewhere. HawkEye 360 offers a useful commercial example. The U.S. company describes a satellite-based RF analytics business that detects, geolocates and characterizes emitters and, in the maritime domain, combines radio-frequency observations with AIS and imagery to identify and track vessels. The comparison does not establish what a merchant ship could collect from sea level and provides no evidence concerning COSCO; it shows instead how signals that appear inconsequential in isolation can acquire operational value once they are located, compared over time and correlated with other datasets.
That process makes hardware an unreliable shortcut for judging purpose. A receiver covering a wide frequency range may support testing or communications work, while software capable of sorting radio data may perform legitimate diagnostic functions and large stores of onboard data are no longer unusual. The information needed to distinguish those uses emerges from operation: which frequencies a system monitored, whether it became active only in particular locations, what its software extracted, how long data were retained and whether those data remained aboard or travelled through another communications path. An apparently capable system becomes significant only when its configuration and operating history begin to narrow the range of ordinary explanations.
Maritime cybersecurity illustrates why seemingly adjacent security problems also need to remain separate. The IACS E26 and E27 requirements govern cyber resilience in onboard computer-based systems, their interfaces and the networks connecting them, with requirements dealing with protection, access, response and recovery. ClassNK’s guidance explicitly notes that E26 and E27 do not directly require countermeasures against GPS spoofing or jamming because those problems concern the authenticity or availability of satellite-positioning signals received from outside the vessel rather than compromise of the ship’s computer systems. A vessel can therefore suffer a cyber intrusion, encounter a manipulated electromagnetic environment or carry equipment intended for intelligence collection without those conditions becoming technically interchangeable.
The same cyber-resilience regime also illustrates how technical documentation may become increasingly important beyond the purpose for which it was originally created. ClassNK requires asset inventories and network documentation for covered computer-based systems, including ship-specific records identifying hardware and software configurations. These inventories are designed to demonstrate cyber compliance, not to support counterintelligence investigations, and they do not amount to a complete catalogue of every electronic component aboard a ship. Their usefulness lies in the principle they embody: an unexplained system is easier to recognize when there is an authoritative account of what should normally be present and how the expected systems are connected.
That principle becomes harder to apply across a fleet built under several generations of regulation, because merchant ships rarely retain the technical configuration they had when delivered. Satellite terminals are replaced, navigation and communications equipment are upgraded, software changes and new systems are added during decades of service, which means that even vessels constructed to similar designs can later present very different electronic architectures without either having departed from legitimate commercial practice. A useful baseline therefore has to describe the individual ship and its modification history rather than an idealized vessel of its class.
What the Public Record Can Establish
China’s maritime organization gives foreign governments reason to examine the potential use of civilian vessels for intelligence purposes seriously. Ryan Martinson of the U.S. Naval War College’s China Maritime Studies Institute documented in 2025 that collecting and reporting maritime intelligence is a core mission of China’s maritime militia, whose reconnaissance units help fill gaps in the People’s Liberation Army’s situational awareness. His research also reaches beyond the coastal militia itself: given China’s expanding overseas maritime presence, Martinson argues that Chinese distant-water fishing vessels and Chinese-owned or operated merchant ships provide latent intelligence, surveillance and reconnaissance capacity, while PLA specialists have advocated placing intelligence personnel aboard Chinese ships operating overseas.
That research gives the Reuters allegation a strategic context without proving it. Martinson’s report primarily documents the maritime militia and assesses the potential value of other civilian platforms; it does not identify the COSCO vessels described by the U.S. officials, examine equipment aboard them or establish that a particular commercial voyage doubled as an intelligence mission. The difference is fundamental. A military institution’s documented interest in using civilian maritime networks makes such activity a credible subject for investigation, but it cannot establish that the activity occurred aboard an unidentified vessel in an unidentified location.
The same evidentiary discipline applies when state ownership and China’s broader civil-military structure enter the analysis. Such relationships may properly influence how an intelligence agency evaluates risk, access and the possibility of government tasking, particularly when assessing a large state-owned carrier. They still cannot reveal what a particular system aboard a particular hull did during a specific voyage. Political structure can tell investigators where closer scrutiny may be warranted; attribution requires evidence tied to actual conduct.
Reuters’ account consequently remains strongest as a report of a U.S. intelligence assessment rather than a publicly reproducible technical case. The officials described an established relationship between COSCO and Chinese intelligence and attributed a specific military purpose to the alleged collection, yet the public has not been given the vessels, equipment or data chain on which that conclusion rests. Such a gap is common in national-security reporting because intelligence services may combine satellite observations, technical signatures, communications intercepts, human reporting and information supplied by allies, while releasing any one of those elements may reveal how an operation was discovered or how a foreign system is being monitored.
A classified assessment may therefore be persuasive inside government before it is capable of independent verification outside it, but journalism works under a different evidentiary constraint. The more consequential an allegation becomes, the more carefully reporting has to separate what open sources demonstrate from what officials say they have established through information that remains unavailable for examination. In the COSCO case, the public record demonstrates that Chinese military analysts see intelligence value in civilian maritime platforms and that American officials now allege actual collection aboard company vessels; those propositions are related, but the first cannot be used to fill the evidentiary gap in the second.
The distinction carries practical economic consequences because COSCO is not a specialized surveillance vessel operating outside normal commerce. It is a major carrier embedded in liner routes, terminals and supply chains that cross jurisdictions and political alignments. Credible intelligence about a particular ship may justify highly targeted scrutiny, while treating the commercial network surrounding a state-owned carrier as confirmed intelligence infrastructure without vessel-specific evidence would extend the consequences far beyond the object of the original suspicion. Security decisions become more defensible as the information becomes more specific: a named ship, an identifiable technical system, a documented operating pattern and evidence indicating where collected data travelled.
Maritime Law Is Not Starting From Zero
Rapid technological change often produces a familiar argument in which rules written for an earlier period prove unable to accommodate a new threat. Maritime intelligence collection does not fit comfortably into that narrative because international law already recognizes that commercial vessels can engage in activity incompatible with ordinary passage, while contemporary maritime-security rules reach further into electronic systems than their post-September 11 origins might suggest.
The United Nations Convention on the Law of the Sea states that passage through a coastal state’s territorial sea remains innocent only while it is not prejudicial to the state’s peace, good order or security. Article 19 then identifies among the activities incompatible with innocent passage “any act aimed at collecting information to the prejudice of the defence or security of the coastal State.” The provision does not transform every sophisticated receiver into a legal violation; it addresses conduct and therefore still requires a factual basis for concluding that harmful collection is occurring. What it establishes is that commercial status does not make intelligence activity legally invisible simply because the platform conducting it happens to be a merchant ship.
The evidentiary problem becomes particularly apparent with passive collection. A state may possess clear legal authority to respond to intelligence collection in its territorial sea while finding it considerably harder to establish that a receiver aboard an otherwise ordinary commercial vessel is being used for precisely that purpose. Technical examination may reveal what frequencies a system can receive, but frequency coverage alone does not establish what was collected during a voyage or whether the activity harmed national defence or security. Legal clarity and factual certainty do not necessarily arrive together.
Once a vessel approaches or enters port, SOLAS Chapter XI-2 and the ISPS regime provide additional tools. IMO guidance allows governments to inspect, delay, detain or restrict a ship when clear security grounds exist, and the guidance specifically recognizes that reliable information concerning a vessel may provide such grounds before inspectors have discovered a visible deficiency during a routine onboard check. A state may also direct an approaching ship to a specified location in territorial or internal waters so that an inspection can be carried out before normal port operations proceed.
The security-assessment framework itself reaches beyond access controls and physical threats. IMO guidance lists radio and telecommunications systems, including computer systems and networks, among the elements to be examined in a ship security assessment and also includes areas that could pose a risk if used for illicit observation. The presence of those categories does not give inspectors an automatic method for determining the purpose of an unexplained receiver, but it undermines the assumption that contemporary maritime-security rules recognize only weapons, unauthorized persons and perimeter breaches.
South Korea has incorporated that international architecture into its own port-security regime. Foreign vessels intending to enter Korean ports generally have to submit Ship Security Information through PORT-MIS at least 24 hours before arrival, and the Busan Regional Office of Oceans and Fisheries states that deficiencies identified through the process can result in movement restrictions, corrective measures, inspection or refusal of entry. Korean law separately requires the Ministry of Oceans and Fisheries to designate security supervisors and permits the ministry to demand reports or supporting documents and, where document review is insufficient, send supervisors directly aboard vessels or into port facilities to inspect security matters.
These powers matter because they show that the central weakness is not obviously an absence of legal authority. Credible intelligence can alter the treatment of a foreign vessel, security officials can inspect it, and international law already contains a category for intelligence collection harmful to a coastal state. What none of these rules can supply automatically is the technical conclusion on which their most consequential use may depend. A law can authorize officials to examine equipment; it cannot tell them what an unfamiliar receiver was programmed to monitor or whether data found aboard were collected for a commercial, technical or intelligence purpose.
The quality of the response therefore depends increasingly on the quality of the evidence brought into the legal process. Intelligence can identify a particular vessel or system worth examining; ship records can establish an expected configuration; technical inspection can determine whether actual equipment departs from it; logs and data may reconstruct operation; and national-security information may eventually explain why a particular pattern matters. Existing powers become more useful as those forms of evidence converge and less useful when suspicion remains broad.
Busan Needs Precision More Than Suspicion
Busan turns the problem from maritime-security theory into the daily economics of a global port. Busan Port Authority recorded 24.882 million TEU of container traffic in 2025, of which 14.097 million TEU were transshipment cargo—approximately 56.7 percent of the total. More containers therefore passed through Busan on their way between foreign origins and destinations than moved through the port as Korean import-export cargo, a structure that depends on the predictable circulation of ships, boxes and connecting services across national and corporate boundaries.
A transshipment port cannot make foreignness an operational anomaly because foreignness is part of its business model. Its terminals routinely serve ships registered under different flags, owned by private companies and state-linked groups, participating in multinational shipping alliances and carrying electronics certified under several regulatory systems. Nationality and ownership may matter when combined with concrete security intelligence, but used alone they would identify far too much ordinary traffic to function as useful screening criteria.
The same is true of technological sophistication. A vessel equipped with advanced satellite communications, extensive onboard computing and multiple receivers is no longer unusual enough for those characteristics to justify intensive scrutiny by themselves. Effective inspection instead requires some understanding of the individual ship’s expected configuration and operating history, because the meaningful signal is more likely to be a deviation that cannot be accounted for by normal modifications than the simple presence of capable equipment.
False positives matter in that environment for reasons that extend beyond inconvenience to a single ship. An unnecessary delay can disrupt a berth window, which can interfere with container transfers and connecting liner services, particularly in a hub where a large share of cargo is scheduled to move from one vessel to another rather than leave the port immediately. Security concerns can of course outweigh those costs when the underlying intelligence is credible, but the potential for cascading disruption makes specific intelligence more valuable than broad suspicion: identifying one hull, one system or one period of anomalous operation allows authorities to concentrate resources without imposing the same friction on a much wider flow of legitimate trade.
COSCO’s commercial presence in global liner networks illustrates why the distinction must remain intact. The allegation reported by Reuters makes company vessels a legitimate subject of attention when governments possess specific supporting intelligence, yet no public evidence currently connects COSCO’s ordinary calls at Busan with the alleged collection activity. Treating the carrier’s presence at the port as evidence in itself would therefore collapse the very distinction the investigation is meant to establish.
A stronger security model begins with better baselines. Computer-system asset inventories developed for cyber-resilience compliance offer only part of such a baseline, but they illustrate how authorities, shipowners and classification societies can improve visibility into the systems legitimately installed aboard particular vessels. Maintenance histories, modification records, network diagrams and technical documentation can add context, while targeted inspection becomes more productive when officials know what they are trying to confirm or disprove rather than searching a large vessel for an undefined threat.
No baseline will eliminate uncertainty from a global fleet in which ships remain in service for decades and accumulate legitimate technical changes along the way. Precision does not mean classifying every undocumented difference as suspicious; it means reducing uncertainty until genuinely unexplained behavior can be distinguished from the ordinary variation produced by repairs, upgrades and changing commercial requirements. That approach demands more technical expertise than categorical screening, but it also produces fewer false positives and stronger evidence when an anomaly proves significant.
The challenge will grow as merchant ships become more heavily instrumented. In 2026 the IMO adopted its first global safety code for Maritime Autonomous Surface Ships and introduced VDES into its regulatory framework as a more capable successor to AIS, with stronger data exchange and authentication intended to improve maritime communications and tracking. Remote and autonomous operations will continue adding sensors, software, processors and ship-to-shore connections for entirely legitimate purposes, further raising the level of electronic sophistication that port authorities must treat as normal.
The consequence is counterintuitive. As ordinary ships become more technologically capable, technological capability by itself becomes less useful as a security indicator. An antenna that might once have attracted attention may become part of a routine communications suite; a powerful onboard processor may support autonomous navigation; additional sensors may exist because the vessel operates with fewer crew members and greater remote oversight. Investigators will increasingly have to understand relationships among systems and patterns of operation rather than rely on the discovery of a conspicuous piece of hardware.
Evidence of intelligence activity would therefore have to accumulate through context. A system whose operation cannot be reconciled with the vessel’s documented functions becomes more significant if logs show that it repeatedly collected particular signals in sensitive locations; the case grows stronger if stored data confirm what was acquired and stronger again if network records or other intelligence show where the information went and who directed the collection. Attribution arrives through the convergence of those findings, not through technological sophistication alone.
Governments will sometimes possess enough classified information to reach that conclusion without publishing the material required for outsiders to reproduce it, leaving a persistent tension between official confidence and public verification. The COSCO allegation may eventually be supported by additional disclosure, weakened by contrary evidence or remain largely within classified assessments. Any of those outcomes would matter for the company and the governments receiving its vessels, but the technical problem exposed by the allegation would remain.
Merchant ships are already mobile information systems moving through some of the world’s most economically and strategically important coastal environments. International and Korean law give authorities substantial room to respond when credible information identifies harmful activity, while modern maritime-security rules already recognize communications and computer systems as part of the security environment. The more difficult task is increasingly evidentiary: knowing what normally belongs aboard a particular vessel, recognizing when its systems depart meaningfully from that baseline, reconstructing what an anomalous system actually did and connecting the resulting technical record to an actor and purpose before suspicion hardens into attribution.
For Busan, whose value comes from bringing competing shipping networks into the same operational space, the answer cannot be to make global trade less global. A port that maximizes suspicion would eventually undermine the connectivity on which its competitiveness depends, while a port unable to test credible intelligence against technical evidence would expose the same connectivity unnecessarily. The more durable advantage lies in precision—an ability to understand ordinary shipboard technology well enough that the small number of systems performing an extraordinary function can be identified without making ordinary international commerce itself the suspect.
Continue this reporting
Reporting on the same issue
Related coverage selected from the article's desk, topics and newsroom relationships.
NewsAug 23, 2026When Smart Glasses Stop Looking Like Computers
The most successful smart glasses are learning to disappear. Their next chall...
NewsAug 15, 2026Busan Port’s Next Automation Challenge Lies Between the Machines
Busan New Port already runs driverless cargo transport. Its next automation p...
NewsJul 26, 2026Why Nvidia Is Betting on South Korea’s Factories
Nvidia needs more than chips and data centres to make physical AI work. Korea...
More from the author
More from this byline
Stay with the same line of reporting through more work from this byline.
NewsAug 28, 2026The Reactor Built for a Different Grid
Editorial Record
Corrections, sourcing notes and newsroom disclosures remain part of the published record. View Newsroom Notes →
Reader Signal
Community readWhat did this report leave you with?
Choose the signal that best reflects your reading. Select it again to remove it.
One response per article
No response selected
A moderated conversation about the reporting.
One-level replies and newsroom moderation keep the conversation anchored to this article.
Discussion Status
Open
Please sign in to join the discussion.
Newsletter
Weekly reporting and context from Busan and Korea.
